IPv6 Subnet Calculator With Prefix and Child Networks

128-bit prefix and allocation map

IPv6 Subnet Calculator

Expand and normalize an IPv6 address, apply any /0 through /128 prefix, and plan child prefixes without importing IPv4 broadcast assumptions. Exact power-of-two counts are built as decimal strings, preserving all 128-bit address capacity.

Enter an IPv6 address and prefix plan

IPv6 prefix map

Canonical containing prefix2001:db8:abcd::/48
Fully expanded network2001:0db8:abcd:0000:0000:0000:0000:0000
Last mathematical address2001:db8:abcd:ffff:ffff:ffff:ffff:ffff
Addresses in containing prefix2^80 = 1,208,925,819,614,629,174,706,176
Child /64 prefixes2^16 = 65,536
First child prefix2001:db8:abcd::/64
Last child prefix2001:db8:abcd:ffff::/64

128-bit boundary audit

Containing prefix bits: 48 Child subnet-selection bits: 16 Bits remaining inside each child: 64 IPv6 has no broadcast address; the displayed last value is only the numerical end of the prefix.

What an IPv6 prefix means

An IPv6 address is a 128-bit identifier written as eight groups of 16 bits, called hextets. Each hextet is normally written with one to four hexadecimal digits. A prefix length states how many contiguous bits from the left identify the prefix. The remaining bits vary within that prefix.

The entered address may be one interface address inside a much larger allocation. Applying /48 to the default address keeps the first 48 bits—three complete hextets—and clears the remaining 80 bits. The canonical containing prefix becomes 2001:db8:abcd::/48.

IPv6 has unicast, anycast, and multicast addressing but no broadcast addresses. The calculator displays the largest numerical address in the prefix only as a range endpoint. It never labels that endpoint “broadcast” and does not subtract network and broadcast values from an imagined usable-host count.

The 128-bit mapping process

1. Expand text

Resolve a single :: compression marker and restore omitted zero hextets until exactly eight 16-bit groups exist.

2. Validate hexadecimal

Each explicit group must contain one through four hexadecimal digits. This calculator does not parse embedded dotted-decimal IPv4 notation.

3. Apply prefix bits

Keep the leftmost prefix bits and set every remaining bit to zero for the canonical network prefix.

4. Split allocation bits

Bits between containing prefix and child prefix select child subnets. Bits after the child prefix remain within each child.

Worked example: one /48 divided into /64s

The default address lies inside 2001:db8:abcd::/48. A /48 leaves 80 bits within the containing prefix, so its mathematical capacity is 2⁸⁰ addresses. The exact decimal value is 1,208,925,819,614,629,174,706,176.

Choosing /64 child allocations consumes 16 of those 80 bits as a subnet identifier. That creates 2¹⁶ = 65,536 distinct /64 prefixes. The first is 2001:db8:abcd:0::/64, canonically compressed as 2001:db8:abcd::/64. The last is 2001:db8:abcd:ffff::/64.

Each /64 contains 2⁶⁴ mathematical addresses. That large host field should not encourage sequential scanning or manual host inventories. IPv6 address planning generally focuses on prefix hierarchy, routing, security zones, link purpose, and address-assignment mechanisms.

Expansion and zero compression

Leading zeros

Within a hextet, leading zeros may be omitted. 0db8 can be written db8. At least one digit remains unless the group participates in :: compression.

One double colon

:: replaces one or more consecutive all-zero hextets and may appear only once in one address. Its expansion depends on the number of groups already written.

Canonical compression

The result uses lowercase hexadecimal and compresses the longest run of two or more zero hextets. If runs tie, the leftmost is chosen.

Prefix notation

An address and decimal prefix length are joined with a slash. Host bits written to the left of the slash do not alter which canonical network contains the address.

A huge count is not a host-capacity recommendation

The mathematical number of values in a prefix does not tell how a link should be designed. Address architecture, standards, router advertisements, SLAAC, DHCPv6, privacy addresses, stable addresses, neighbor discovery, platform requirements, and organizational policy determine use.

A /64 is common for many IPv6 links and is important to mechanisms that expect a 64-bit interface identifier, but not every prefix in every context must represent an ordinary LAN. Point-to-point links, loopbacks, delegations, and specialized systems can use other lengths under applicable guidance. Do not select a smaller host field solely to imitate IPv4 conservation.

All-zero and all-one field values are generally legal in IPv6 unless another rule excludes them. There is no universal “subtract two” usable-address formula. Cloud platforms and products can still reserve particular values for their services, so consult platform documentation.

Build an IPv6 allocation hierarchy

Start with the prefix actually delegated by an ISP, registry, cloud provider, tunnel broker, lab, or parent organization. Decide which bits represent region, site, environment, security zone, function, or link. Keep boundaries on hextet or nibble positions when that improves readability, DNS delegation, and filtering, but do not waste hierarchy merely to make strings pretty.

The child prefix must be equal to or longer than the containing prefix. Each additional allocation bit doubles the number of child prefixes and halves their size. Moving from /48 to /56 creates 256 children; /48 to /64 creates 65,536. The calculator reports the first and last child boundaries, not every entry.

Reserve contiguous space for growth and route aggregation. Assign stable identifiers through an address management system rather than remembering the written suffix. Document delegation owner, purpose, routing scope, DNS, security policy, and lifecycle.

Prefix range and overlap checks

Two IPv6 prefixes overlap when their numerical ranges intersect. A longer prefix can be contained inside a shorter one. Routing normally prefers the longest matching prefix, so an accidental more-specific route can divert only part of a larger allocation.

Compare proposed prefixes with global, unique-local, link-local, multicast, documentation, loopback, transition, VPN, cloud, and lab ranges relevant to the system. Do not infer address type from a convenient nickname; evaluate the high-order bits and current registry or protocol definition.

The default 2001:db8::/32 space is reserved for documentation examples. It should not be used as real global addressing. Replace it with an authorized allocation for deployment, while avoiding the disclosure of sensitive production plans in public tools or documents.

IPv6 differs from IPv4 operations

No broadcast endpoint

Multicast replaces broadcast functions. The numerically last address has no universal IPv4-style directed-broadcast role.

No subtract-two rule

Prefix capacity is 2^(128−prefix). Address assignment rules are contextual; do not remove a network and broadcast value from every subnet.

Neighbor discovery

IPv6 uses Neighbor Discovery rather than IPv4 ARP. Large mathematical ranges do not make indiscriminate neighbor scanning an address-management strategy.

Multiple addresses per interface

An interface commonly has link-local plus one or more other addresses. Inventory and security controls should account for prefixes and address lifetimes.

Verification and handoff checklist

Expand the entered address to eight hextets and count four hexadecimal digits per expanded group. Confirm the canonical network shares exactly the selected leftmost bits and has zeros afterward. Confirm that the last mathematical address has ones afterward. For a /48, the first three hextets should be fixed.

Subtract the containing prefix from the child prefix to obtain subnet-selection bits. Raising two to that difference should match the child count. Subtract child prefix from 128 to obtain bits within each child. Save both expanded and compressed forms in design documentation so humans and systems can compare consistently.

Before deployment, validate the prefix against router, firewall, DNS, IPAM, cloud, and operating-system syntax. Test routing and filtering in a nonproduction change window, preserve rollback steps, and ensure that prefix-based security rules cover temporary and privacy addresses as intended.

Address privacy, logging, and security scope

A large interface field does not make an IPv6 host inherently anonymous or secure. Stable identifiers, temporary privacy addresses, DNS records, application identifiers, traffic patterns, and logs can still associate activity with a device or user. Address generation policy should match operational troubleshooting, privacy requirements, and security monitoring.

Write access controls against the intended prefix hierarchy and traffic role, not one remembered interface address. Interfaces may hold multiple global, unique-local, link-local, stable, and temporary addresses at once. A rule covering only the address first seen during testing can miss later privacy addresses, while an overly broad prefix rule can authorize unrelated systems.

Store IPv6 addresses in fields that preserve 128 bits and compare canonical binary values rather than raw text. The strings 2001:db8::1 and 2001:0db8:0:0:0:0:0:1 represent the same address. Logging systems should retain enough original context for investigation while normalizing for search and correlation.

Do not publish a production allocation map casually. Prefix structure can reveal sites, environments, functions, and routing design. Share only the scope required for operations, audits, or troubleshooting, and protect IPAM exports as infrastructure data.

Frequently asked questions

Does IPv6 have a broadcast address?

No. RFC 4291 states that IPv6 has no broadcast addresses; multicast supersedes their function.

How many addresses are in a /64?

A /64 leaves 64 variable bits, so it contains exactly 2⁶⁴, or 18,446,744,073,709,551,616, mathematical addresses.

Can :: appear twice?

No. One :: marker can compress one run of zero hextets. Two markers would make the omitted group count ambiguous.

Why does the default use 2001:db8?

2001:db8::/32 is documentation space, appropriate for examples but not real global deployment.

Must every child be /64?

No universal rule covers every purpose, but /64 is standard for many ordinary links and supports mechanisms designed around 64-bit interface identifiers. Follow current architecture and platform guidance.

Does the calculator assign an interface address?

No. It maps containing and child prefixes. Address assignment, duplicate detection, DNS, routing, and security remain deployment tasks.

Related calculator

The separate page keeps the protocols’ operational semantics distinct.

References

The address forms, prefix notation, address types, and absence of broadcast follow IETF RFC 4291, IP Version 6 Addressing Architecture. Compressed result formatting follows IETF RFC 5952, A Recommendation for IPv6 Address Text Representation.

Scroll to Top